Executive brief
B2BKing is a WordPress plugin used to manage wholesale and business-to-business operations on WooCommerce stores. A security flaw in the plugin's access control settings could allow high-privileged users, such as Shop Managers, to perform actions or modify settings they should not have permission to access. This could lead to unauthorized changes in store configuration or business rules.
Technical details
A missing authorization vulnerability (CWE-862) exists in the B2BKing plugin for WordPress in versions prior to 5.2.10. The flaw allows an attacker with high-level privileges (specifically the 'Shop Manager' role) to bypass intended access control security levels due to incorrectly configured checks. While the attack requires network access and existing high-level authentication, it enables the modification of data or settings that should be restricted to administrators. The issue is resolved in version 5.2.10.
Affected products
- Kings Plugins B2BKing - Wholesale for WooCommerce before 5.2.10
Timeline
- 2025-11-30: other: Reported by researcher Phat RiO
- 2026-05-25: patched: Patch released in version 5.2.10
- 2026-05-25: disclosed: Public disclosure by Patchstack